Tuesday, 2018-08-21

*** hongbin has joined #openstack-meeting-300:26
*** macza has quit IRC00:41
*** yamahata has quit IRC01:22
*** yamahata has joined #openstack-meeting-301:33
*** isq has quit IRC01:54
*** isq has joined #openstack-meeting-302:02
*** gcb_ has joined #openstack-meeting-302:07
*** yamahata has quit IRC02:15
*** apetrich has quit IRC02:27
*** markvoelker has joined #openstack-meeting-303:01
*** psachin has joined #openstack-meeting-303:06
*** jamesmcarthur has joined #openstack-meeting-303:15
*** jamesmcarthur has quit IRC03:19
*** diablo_rojo has quit IRC03:21
*** hongbin has quit IRC04:10
*** psachin has quit IRC04:27
*** markvoelker has quit IRC04:32
*** markvoelker has joined #openstack-meeting-304:43
*** markvoelker has quit IRC04:52
*** psachin has joined #openstack-meeting-305:14
*** Luzi has joined #openstack-meeting-305:51
*** yamahata has joined #openstack-meeting-306:07
*** alexchadin has joined #openstack-meeting-306:27
*** pcaruana has joined #openstack-meeting-306:42
*** tssurya has joined #openstack-meeting-306:52
*** qwebirc21340 has quit IRC07:08
*** jamesmcarthur has joined #openstack-meeting-307:15
*** jamesmcarthur has quit IRC07:20
*** alexchadin has quit IRC07:21
*** alexchadin has joined #openstack-meeting-307:32
*** macza has joined #openstack-meeting-308:06
*** e0ne has joined #openstack-meeting-308:10
*** macza has quit IRC08:11
*** macza has joined #openstack-meeting-308:48
*** alexchadin has quit IRC08:53
*** macza has quit IRC08:53
*** macza has joined #openstack-meeting-309:09
*** macza has quit IRC09:14
*** alexchadin has joined #openstack-meeting-309:14
*** apetrich has joined #openstack-meeting-309:23
*** macza has joined #openstack-meeting-309:30
*** macza has quit IRC09:35
*** macza has joined #openstack-meeting-310:12
*** jamesmcarthur has joined #openstack-meeting-310:15
*** macza has quit IRC10:16
*** jamesmcarthur has quit IRC10:20
*** alexchadin has quit IRC10:25
*** macza has joined #openstack-meeting-310:33
*** alexchadin has joined #openstack-meeting-310:36
*** macza has quit IRC10:38
*** macza has joined #openstack-meeting-310:54
*** macza has quit IRC10:59
*** zchkun has joined #openstack-meeting-311:13
*** zchkun has quit IRC11:13
*** macza has joined #openstack-meeting-311:35
*** e0ne has quit IRC11:36
*** macza has quit IRC11:40
*** macza has joined #openstack-meeting-312:04
*** numans_ has joined #openstack-meeting-312:07
*** macza has quit IRC12:08
*** numans has quit IRC12:10
*** macza has joined #openstack-meeting-312:11
*** macza has quit IRC12:12
*** raildo has joined #openstack-meeting-312:17
*** Luzi has quit IRC12:28
*** moguimar has quit IRC12:31
*** macza has joined #openstack-meeting-312:35
*** Luzi has joined #openstack-meeting-312:35
*** macza has quit IRC12:40
*** jamesmcarthur has joined #openstack-meeting-312:47
*** jamesmcarthur has quit IRC13:04
*** moguimar has joined #openstack-meeting-313:09
*** psachin has quit IRC13:17
*** rossella_s has joined #openstack-meeting-313:19
*** apetrich has quit IRC13:33
*** e0ne has joined #openstack-meeting-313:40
*** jamesmcarthur has joined #openstack-meeting-313:44
*** alexchadin has quit IRC13:55
*** alexchadin has joined #openstack-meeting-313:58
*** alexchadin has quit IRC14:13
*** alexchadin has joined #openstack-meeting-314:13
*** Luzi has quit IRC14:23
*** munimeha1 has joined #openstack-meeting-314:27
*** Luzi has joined #openstack-meeting-314:36
*** Luzi has quit IRC14:37
*** spilla has joined #openstack-meeting-314:46
*** gagehugo has joined #openstack-meeting-314:51
*** alexchadin has quit IRC14:56
*** hongbin has joined #openstack-meeting-314:56
*** yamahata has quit IRC14:57
*** jamesmcarthur has quit IRC14:57
*** alexchadin has joined #openstack-meeting-314:57
raildo#startmeeting oslo-config-plaintext-secrets15:00
openstackMeeting started Tue Aug 21 15:00:13 2018 UTC and is due to finish in 60 minutes.  The chair is raildo. Information about MeetBot at http://wiki.debian.org/MeetBot.15:00
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
*** openstack changes topic to " (Meeting topic: oslo-config-plaintext-secrets)"15:00
raildoo/15:00
openstackThe meeting name has been set to 'oslo_config_plaintext_secrets'15:00
moguimaro/15:00
spillao/15:01
*** electrichead has joined #openstack-meeting-315:01
electricheado/15:01
* electrichead is aka redrobot15:01
electricheadhaving bouncer issues ... :-\15:01
raildo#link https://etherpad.openstack.org/p/oslo-config-plaintext-secrets15:01
moguimardhellmann bnemec15:02
dhellmanno/15:02
raildohey folks :)15:02
raildo#topic status update15:02
*** openstack changes topic to "status update (Meeting topic: oslo-config-plaintext-secrets)"15:02
*** alexchadin has quit IRC15:03
raildoI updated the spec for stein: https://review.openstack.org/#/c/474304/ updating the phase 0 status and moving that spec for the stein repo15:03
raildowe still need wait for the Denver PTG to get some agreements about the mutable values, so we can focus on approve this spec15:04
raildomoguimar, do you want to talk about the PoC for testing oslo.config driver?15:04
bnemeco/15:04
moguimarsure15:04
moguimarI've setup a remote_file server using docker, nginx and flask15:05
moguimarhttps://github.com/moisesguimaraes/oslo.config-drivers-samples15:05
moguimar#link https://github.com/moisesguimaraes/oslo.config-drivers-samples15:05
moguimarthe nginx does the tls checks15:06
moguimarthe flask app has a crud for configs15:06
moguimarthe config is a simple (id, domain_name, conf)15:06
* gagehugo lurks15:06
moguimarso the server returns configs based on the subject domain name of the client certificate15:07
*** jamesmcarthur has joined #openstack-meeting-315:07
dhellmannare you planning to implement a CI job based on that?15:08
moguimarthat can be used to demo the remote_file driver15:08
moguimarshould I?15:08
dhellmannoh, I don't know, I was just curious15:08
moguimarI'll work on a demo on my own, just for curiosity15:09
*** pcaruana has quit IRC15:09
raildodhellmann, that would be great, but I'm not sure if we'll be able to that upstream, like setting an nginx server and so on, maybe we can evaluate how to adjust it for a CI job15:09
bnemecPython has a very simple HTTP server built in.  Seems like we should be able to use that for a test job.15:10
dhellmannyeah, upstream might just want to reuse whatever devstack does to configure a web front-end for the services15:10
moguimaras I'd like to learn a little about datadog, I would like to see nodes status and they trying to fetch config every x seconds15:10
dhellmannbnemec : that's a good idea, too, although I don't know about the SSL stuff for that15:10
bnemechttps://docs.python.org/2/library/simplehttpserver.html15:10
bnemecYeah, I was thinking just to have basic coverage of this functionality.15:10
raildo#action raildo to investigate more about https://docs.python.org/2/library/simplehttpserver.html15:11
moguimarsimplehttpserver does that job well, the PoC I was working on is something more visual15:13
raildothe next steps for now, will be investigating/playing with castellan-vault and other backends, so we can be more understand more about castellan and start the castellan driver implementation15:13
moguimarI did that castellan deep dive today15:13
moguimarcan you set the topic for it raildo ?15:14
moguimarafter status update15:14
raildo#topic castellan deep dive15:14
*** openstack changes topic to "castellan deep dive (Meeting topic: oslo-config-plaintext-secrets)"15:14
moguimargood15:14
moguimarI cloned the castellan repo and looked into the code15:14
moguimarit stores/retrieves values from vault with a unique ID15:15
moguimarthe IDs are generated with uuid.uuid4().hex15:15
moguimarso I think that the mapping file using the castellan driver should contain option_name=option_id15:16
*** sambetts|afk is now known as sambetts15:16
moguimarthen we just forward the get to castellan15:16
moguimarusing the secret's id15:16
dhellmannthat makes sense15:17
moguimarI hope this approach doesn't care which backend castellan is talking to15:17
moguimarso the castellan driver would work for both vault and barbican15:18
moguimarI15:18
dhellmanndo the id values change format based on the driver at all?15:18
raildomoguimar, yeah, that's why we have to use the castellan reference_id15:18
dhellmannlike sometimes they are uuid and sometimes just numbers?15:18
moguimarwill check that15:18
moguimarhaven't poked the barbican_key_manager file yet15:18
dhellmannok15:18
dhellmannI suspect they don't, but wouldn't want to assume so15:19
dhellmannI guess if we just don't worry about what's in the string for the value it won't matter if the format changes15:19
dhellmannas long as it can be expressed as a value in an ini file we should be safe reading it15:19
raildodhellmann, I think that all of that are using uuid, but would be nice double check that as well15:19
raildodhellmann, ++15:19
moguimarI still have a lot of tests being skipped in tox for castellan15:20
moguimarso I'll poke the castellan folks to find out how to setup vault and barbican for the skipped castellan tests15:20
raildomoguimar, notice that you have to explicitly enable the vault tests for castellan on tox15:21
raildothere is an option on tox for castellan to run the vault tests15:21
raildo#link https://github.com/openstack/castellan/blob/master/tox.ini#L7515:21
moguimaryup15:22
moguimarI'll try that one15:22
raildogreat15:22
raildo#topic Open Discussion15:23
*** openstack changes topic to "Open Discussion (Meeting topic: oslo-config-plaintext-secrets)"15:23
moguimarI supose the full tests also test vault, but it looks for some ENV vars15:23
moguimaras I can see the skipped message15:23
moguimarthat's all I have15:23
raildoit doesn't since it's necessary a vault server, and root key for vault15:23
raildoso it'll run the functional tests, other else, it will just execute the unit tests for that code15:24
moguimaryeah, I have a vault server running, it gets the addr and token from env vars15:25
raildoso, let's try that option and we can see the result with that15:25
moguimaryep15:25
raildoawesome15:25
raildook, so if we don't have nothing else to talk, see you guys in two weeks :)15:26
raildothanks everyone!15:26
moguimaro/15:27
raildo#endmeeting15:27
*** openstack changes topic to "OpenStack Meetings || https://wiki.openstack.org/wiki/Meetings/"15:27
bnemecOh, that reminds me.15:27
openstackMeeting ended Tue Aug 21 15:27:23 2018 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:27
openstackMinutes:        http://eavesdrop.openstack.org/meetings/oslo_config_plaintext_secrets/2018/oslo_config_plaintext_secrets.2018-08-21-15.00.html15:27
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/oslo_config_plaintext_secrets/2018/oslo_config_plaintext_secrets.2018-08-21-15.00.txt15:27
openstackLog:            http://eavesdrop.openstack.org/meetings/oslo_config_plaintext_secrets/2018/oslo_config_plaintext_secrets.2018-08-21-15.00.log.html15:27
bnemecraildo: moguimar: Were you going to be at the PTG?15:27
moguimarnope15:27
raildobnemec, no =/15:27
bnemec:-(15:28
raildobnemec, there will be a few members from our team, that I'll ask them to attend the oslo meeting15:28
raildobnemec, so, they will be aware of that discussion and can help on it15:29
bnemecraildo: Okay, sounds good.  Thanks.15:29
*** gagehugo has left #openstack-meeting-315:31
*** yamahata has joined #openstack-meeting-315:38
*** dklyle has quit IRC15:41
*** dklyle has joined #openstack-meeting-315:44
*** e0ne has quit IRC15:44
*** macza has joined #openstack-meeting-316:00
*** njohnston has joined #openstack-meeting-316:03
*** markvoelker has joined #openstack-meeting-316:50
*** sambetts is now known as sambetts|afk16:52
*** jamesmcarthur has quit IRC17:14
*** yamahata has quit IRC17:17
*** spilla has quit IRC17:35
*** e0ne has joined #openstack-meeting-317:42
*** jamesmcarthur has joined #openstack-meeting-317:49
*** tssurya has quit IRC17:50
*** numans_ has quit IRC17:54
*** diablo_rojo has joined #openstack-meeting-317:56
*** yamahata has joined #openstack-meeting-317:58
*** apetrich has joined #openstack-meeting-318:02
*** jamesmcarthur has quit IRC18:08
*** mjturek has joined #openstack-meeting-318:10
*** NobodyCam has quit IRC18:37
*** lamt has quit IRC18:37
*** Adri2000 has quit IRC18:37
*** leifz has quit IRC18:37
*** vkmc has quit IRC18:37
*** ttx has quit IRC18:37
*** alaski has quit IRC18:37
*** kencjohnston has quit IRC18:37
*** fungi has quit IRC18:37
*** kencjohnston_ has joined #openstack-meeting-318:38
*** vkmc has joined #openstack-meeting-318:40
*** fbouliane has quit IRC18:42
*** TheJulia has quit IRC18:42
*** tobberydberg has quit IRC18:42
*** fyx has quit IRC18:42
*** fbouliane has joined #openstack-meeting-318:46
*** fungi has joined #openstack-meeting-318:48
*** isq_ has joined #openstack-meeting-318:54
*** e0ne has quit IRC18:57
*** isq has quit IRC18:57
*** isq_ has quit IRC18:58
*** isq has joined #openstack-meeting-318:58
*** TheJulia has joined #openstack-meeting-319:01
*** jamesmcarthur has joined #openstack-meeting-319:11
*** jamesmcarthur has quit IRC19:15
*** bnemec has quit IRC19:20
*** bnemec has joined #openstack-meeting-319:20
*** melwitt has quit IRC19:33
*** sdake has quit IRC19:33
*** melwitt has joined #openstack-meeting-319:34
*** sdake has joined #openstack-meeting-319:34
*** PagliaccisCloud has quit IRC19:39
*** timothyb89 has quit IRC19:39
*** Neptu has quit IRC19:39
*** sambetts|afk has quit IRC19:42
*** Neptu has joined #openstack-meeting-319:43
*** sambetts_ has joined #openstack-meeting-319:45
*** PagliaccisCloud has joined #openstack-meeting-319:46
*** njohnston has left #openstack-meeting-319:55
*** beisner_ has joined #openstack-meeting-320:12
*** gmann_ has joined #openstack-meeting-320:13
*** moguimar has quit IRC20:19
*** dobson has quit IRC20:19
*** beisner has quit IRC20:19
*** gmann has quit IRC20:19
*** gmann_ is now known as gmann20:19
*** beisner_ is now known as beisner20:19
*** jamesmcarthur has joined #openstack-meeting-320:22
*** jamesmcarthur has quit IRC20:26
*** raildo has quit IRC20:46
*** jamesmcarthur has joined #openstack-meeting-320:58
*** ildikov has joined #openstack-meeting-321:02
*** harlowja has joined #openstack-meeting-321:02
*** mjturek has quit IRC21:08
*** munimeha1 has quit IRC21:21
*** jamesmcarthur has quit IRC21:48
*** jamesmcarthur has joined #openstack-meeting-321:50
*** jamesmcarthur_ has joined #openstack-meeting-321:52
*** jamesmcarthur_ has quit IRC21:55
*** jamesmcarthur has quit IRC21:55
*** jamesmcarthur has joined #openstack-meeting-321:56
*** jamesmcarthur has quit IRC22:01
*** jamesmcarthur has joined #openstack-meeting-322:04
*** jamesmcarthur has quit IRC22:08
*** diablo_rojo has quit IRC22:44
*** hongbin has quit IRC22:44
*** diablo_rojo has joined #openstack-meeting-322:48
*** macza has quit IRC23:37
*** jamesmcarthur has joined #openstack-meeting-323:39
*** jamesmcarthur has quit IRC23:44

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!